Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gladysassistant
Gladysassistant gladys Assistant |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:gladysassistant:gladys_assistant:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gladysassistant
Gladysassistant gladys Assistant |
|
| Metrics |
cvssV3_1
|
Sat, 21 Sep 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-21T00:00:00
Updated: 2024-09-23T15:26:54.395Z
Reserved: 2024-09-21T00:00:00
Link: CVE-2024-47210
Updated: 2024-09-23T15:26:47.395Z
Status : Awaiting Analysis
Published: 2024-09-21T23:15:14.137
Modified: 2024-09-26T13:32:55.343
Link: CVE-2024-47210
No data.
ReportizFlow